Senior Manager of Information Security

Morningstar Inc

Hybrid Actively hiring
Chicago, IL · Toronto, ON Posted 11 days ago $147,550$226,233 / year

At a glance

AI generated

TL;DR

The IT Compliance Manager role within the Information Security department at Morningstar involves leading and managing a team focused on ensuring compliance with information security standards such as SOX, SOC2, PCI-DSS, and GDPR. This individual will execute audit tests, manage third-party risk assessments, and collaborate closely with internal and external auditors to maintain efficient and effective processes that adhere to regulatory requirements. The role demands strong leadership skills for managing cross-functional teams, expertise in governance frameworks like NIST and ISO, and the ability to multitask under pressure while ensuring compliance across all business units. Candidates should have a bachelor’s degree and at least five years of experience in risk management or IT auditing, along with relevant certifications such as CISSP or CISM.

Skills

SOX SOC2 PCI-DSS GDPR SEC NIST ISO COBIT CISSP CISM CIPP

What you'll do

  • Lead and manage the Information Security Compliance team to ensure adherence to SOX, SOC2, PCI.
  • Execute compliance status reporting and metrics for information security and IT processes.
  • Manage periodic reviews of security policies, processes, and procedures.
  • Conduct third-party risk management program and contract reviews for client security contracts.
  • Monitor and enforce compliance with information security and compliance policies and standards.
  • Liaise with internal, external, and client auditors to facilitate audits as required.

What we're looking for

  • 5+ years of experience in risk management, compliance, or IT auditing.
  • Strong leadership and team development skills with cross-functional/global team management.
  • Expertise in implementing governance frameworks like NIST, ISO, COBIT.
  • Excellent communication skills and familiarity with key compliance standards (SOX, SOC2, PCI-DSS).
  • Demonstrated ability to manage third-party risk and conduct contract reviews.
  • Proven track record of leading strategic information security compliance programs.

Market check

Salary context

This $147,550–$226,233 range sits above 61% of similar postings on FindRole.

Peer median band

$130,147$220,000

Median floor and ceiling across peers.

Typical midpoint (25–75%)

$145,200$216,065

Middle half of comparable postings.

Based on 240 comparable postings.

* 240 is the maximum number of comparable postings sampled.

Employer

About Morningstar Inc

Morningstar, Inc. is a leading financial services firm providing independent investment research, data, and management services to individuals, advisors, and institutions.

Morningstar Inc currently has 12 open roles on FindRole.

Listed pay typically runs $114,100–$167,350 across 12 roles with salary data.

Most-posted roles

View all roles at Morningstar Inc

More like this

Similar roles

Manager of Information Security

Morningstar Inc

Chicago, Illinois, US 9 days ago $147,550$147,550
SOX SOC2 PCI-DSS GDPR SEC NIST ISO COBIT CISSP CISM CIPP

Senior Security Manager

Leidos

7068 Baltimore Md, US 16 days ago $131,300$237,350
Microsoft 365 Windows VDI Exchange Online SharePoint Online OneDrive Teams MFA DLP NIST FISMA CI/CD Git Azure AWS Kubernetes Terraform Python PostgreSQL Prometheus Grafana

Senior Manager, System Software Security

Nvidia

Us, Ca, Santa Clara, US 49 days ago $272,000$431,250
TEE OP-TEE TrustZone RiscV HSM ARM TrustZone DRM HDCP SMMU SELinux ISO 21434 UNECE regulation ASIL C C++ Threat modeling Security risk classification AI/ML security LLM security NVIDIA Tegra security stack Post-quantum cryptography ML-DSA EdDSA Virtualization security

Senior Information System Security Officer

Leidos

2143 Annapolis Junction Md, US 14 days ago $131,300$237,350
IAVA SSP TS/SCI Polygraph CI/CD DoD 8570 IAT IAM Encryption Communication Protocols Hardware Security Software Security Security Evaluations Information Systems Security Policies Day-to-Day Security Operations

Information Systems Security Manager

Leidos

2652 Arlington Va, US 42 days ago $107,900$195,050
RMF NIST DISA DoD STIGs JSIG eMASS DRAM ACAS Splunk CI/CD Terraform AWS Kubernetes Python PostgreSQL Git Jenkins Ansible Docker